Package Health

commitizen

Git commit, but play nice with conventions.

Latest 4.3.2NPMNPM

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Health Score Breakdown

Dependency profilecaution

Fourteen runtime dependencies create a meaningful maintenance surface for a command-line tool, but the package has a long release history and an established repository.

Lifecycle scriptscaution

The package runs a prepare lifecycle script during installation, which adds install-time behavior and modest dependency risk even though no maliciousness conclusion follows from it.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months, a meaningful maintenance warning despite the recent package release and repository push.

Repo toolingcaution

The repository uses established build tooling, but no security scanning tools were detected, leaving a security-process gap.

Security policycaution

The repository has no published security policy, reducing transparency around vulnerability reporting and response.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
glob
Version 7.2.3
—
—
dedent
Version 0.7.0
—
—
lodash
Version 4.18.1
—
—
is-utf8
Version ^0.2.1
—
—
cachedir
Version 2.4.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
11 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform